Reloading firmware means writing a fresh, complete firmware image to your miner’s control board — either to move to a newer version (an upgrade), to overwrite a corrupted or misbehaving install with a clean copy (a reflash), or to bring a bricked unit back from a dead web interface (a recovery flash). All three are the same underlying act: replacing the software that runs the miner. This guide is the general playbook for every ANTMINER model. For the click-by-click download steps, follow How to Download and Install Miner Firmware — this page covers the wider picture: when to reload, how to recover a unit whose web UI is gone, and how to do it without bricking the board.
Which kind of reload do you actually need?
- Routine upgrade — The miner boots, hashes, and reaches the web dashboard, but you want a newer feature set, a security fix, or better tuning. Flash from the web interface.
- Clean reflash / factory recovery — The unit boots but behaves badly: garbled config, refused logins, a failed prior upgrade, or a suspected malware infection. Write the stock image back over the top to return it to a known-good state.
- Recovery flash — The web interface never loads, the miner sits in a boot loop, or a previous flash was interrupted. The web method is unavailable, so you write firmware directly to the control board (typically via SD card on older Zynq-based S9/S15/S17-class boards).
Diagnose before you flash. Firmware only fixes software faults. A dead hashboard, a domain that won’t power up, or a failing PSU will survive any number of reflashes — work those with the ASIC Fault Finder first.
Before you flash: pre-flight checklist
- Confirm the exact model. Firmware is model-specific and often board-revision-specific. An S19 image is not an S19 Pro image; an S17 is not a T17. Flashing the wrong file is the most common way people brick a board.
- Get the image from the manufacturer’s official portal only. Download signed stock firmware straight from the vendor’s own support/download site. Never flash a random file from a forum, a marketplace listing, or a re-upload — that is exactly how compromised firmware spreads. Where the vendor publishes a checksum, verify it before flashing.
- Record your settings. A reflash can wipe pool URLs, worker names, and network config. Note your pool addresses, wallet/worker, and any static IP so you can re-enter them after.
- Stabilise power and network. Flash over a wired Ethernet link, never Wi-Fi through a bridge. Put the miner on stable mains — an interruption mid-write is what turns an upgrade into a recovery job. Confirm your PSU matches the unit: APW3/APW5/APW7/APW8/APW9/APW9+ tolerate 110/120V at reduced output, but APW12 and APW17 are 200–240V only.
- Do not open the downloaded file. Save it to disk and hand it to the miner’s uploader. On macOS, disable “open safe files after downloading” so the archive isn’t unpacked.
Upgrading or reflashing from the web interface
- Log in to the miner dashboard on its LAN IP.
- Open the firmware/upgrade panel (on stock Antminer software this is under
System → Upgrade). - Browse to the saved firmware file and start the flash. If the panel offers a “keep settings” checkbox, clear it when your goal is a clean recovery — a full wipe removes corrupted config and is the correct choice when cleaning a suspected infection.
- Leave the miner powered and untouched. Do not close the browser, cut power, or reboot while it writes. After the success message, give it roughly 20 minutes to finish, settle, and re-tune before you judge the result.
A successful stock flash reports “System Upgrade Success.” If an older S9 upgrade fails partway, the unit usually drops to a state that needs the SD-card recovery path below rather than another web attempt.
Recovery flash when the web UI is dead
If the dashboard never comes up or a flash was interrupted, older Zynq-based control boards (S9/S15/S17-class) can be re-imaged from a microSD card: write the manufacturer’s recovery image to the card, set the board to boot from SD, power on, wait for the flash to complete, then remove the card and boot normally. This overwrites the on-board firmware directly, bypassing the broken software. Newer control-board generations use their own vendor recovery procedure — follow the maker’s documented method for that model rather than forcing an SD image that was never built for it.
After any recovery flash the network config resets, usually to DHCP. Find the miner’s new address with your router’s client list, an ARP scan (ARP resolves an IP to its MAC), or Bitmain’s IPReporter — with IPReporter you press the miner’s IP-report button and the unit answers a broadcast with its address; it is not a MAC-to-IP lookup.
Reflashing to remove a malware infection
ASIC miners ship with well-known default credentials and are a standing target when exposed to the open internet. If you suspect a compromise, keep it strictly defensive: change the default root/root login to a strong unique password, put mining gear on an isolated LAN or VLAN that cannot reach — and cannot be reached from — the public internet, and run only official signed firmware. To actually clean an infected unit, do a full factory reflash (a fresh signed image with settings wiped, not “keep config”), then re-apply hardened credentials before it rejoins any network. Bitmain also publishes its own antivirus/immunisation tooling for affected Antminer generations; run that from the official source if your model is covered.
Verify the reload worked
- Web dashboard loads and reports the expected firmware version.
- All three hashboards (Chain0/Chain1/Chain2) enumerate their full chip count with no missing ASICs.
- Hashrate climbs to the model’s rated range and holds after the ~20-minute settle.
- Pool/worker and network settings are correct — re-enter them if the flash wiped them.
- Chip temperatures and fan speeds are sane, not pinned or alarming.
Common mistakes
- Flashing the wrong model or board revision — verify the exact unit first.
- Cutting power or closing the browser mid-flash — the single fastest way to brick a board.
- Using a re-hosted or “modded” image from an untrusted source instead of the vendor’s signed release.
- Flashing to fix what is really a hardware fault — a dead board or bad PSU won’t reload away.
- Forgetting to re-secure the miner after a wipe, leaving default credentials live on a reachable network.
When to escalate
If a unit refuses every reflash and recovery attempt, the fault is almost certainly hardware — a corrupt NAND, a damaged control board, or a power fault upstream of the software. That is a bench-repair job.
Related: Look up your model’s flashing and reset procedure in the miner manuals, source control boards and components from ASIC Repair Parts, or hand a hardware-faulted unit to the bench via Start a Repair.
